You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[Coverage Report] Test Coverage Report — 2026-10-10
#9780
Security-critical files are fully covered on statements and functions.host-iptables.ts, squid-config.ts, and docker-manager.ts are at 100% statements, branches, and functions.
src/domain-patterns.ts has a branch gap. Branch coverage is 89.47%, with 2 uncovered if branches and 1 uncovered switch branch.
src/cli.ts has the weakest security-critical branch coverage. Statements are 85.71% and branches are 50%.
New NVX/storage-propagation code is largely untested.src/nvx/cleanup-registry.ts (42.8% stmts) and src/bounded-execution/finite-cardinality.ts (46.03% stmts) are the lowest-covered files, flagged CRITICAL in the gaps brief.
🎯 Recommendations
High
Add tests for src/nvx/cleanup-registry.ts (42.8% stmts, 32.11% branch) and src/bounded-execution/finite-cardinality.ts (46.03% stmts, 35.29% branch). Cover cleanup and cardinality-limit branches first.
Close the src/domain-patterns.ts branch gap (89.47%). Add cases for the uncovered if and switch branches, since this file validates domain input for the allowlist.
Medium
3. Raise branch coverage in src/cli.ts (50%). Focus on option-parsing and error-path branches.
4. Add tests for the storage-propagation helpers (createStoragePropagationEvidence, observeStorageMount, assertPrivateStorageMount) and for resolveRunSandboxBackend / validateRunSandboxBackend, added in the last 7 days.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
📊 Test Coverage Report — 2026-10-10
Overall Coverage
🛡️ Security-Critical Path Status
📋 Coverage Table
🔧 Function Audit
📅 Recent Source Changes (last 7 days)
Newly added exported functions in the last 7 days:
🔎 Notable Findings
host-iptables.ts,squid-config.ts, anddocker-manager.tsare at 100% statements, branches, and functions.src/domain-patterns.tshas a branch gap. Branch coverage is 89.47%, with 2 uncoveredifbranches and 1 uncoveredswitchbranch.src/cli.tshas the weakest security-critical branch coverage. Statements are 85.71% and branches are 50%.src/nvx/cleanup-registry.ts(42.8% stmts) andsrc/bounded-execution/finite-cardinality.ts(46.03% stmts) are the lowest-covered files, flagged CRITICAL in the gaps brief.🎯 Recommendations
High
src/nvx/cleanup-registry.ts(42.8% stmts, 32.11% branch) andsrc/bounded-execution/finite-cardinality.ts(46.03% stmts, 35.29% branch). Cover cleanup and cardinality-limit branches first.src/domain-patterns.tsbranch gap (89.47%). Add cases for the uncoveredifandswitchbranches, since this file validates domain input for the allowlist.Medium
3. Raise branch coverage in
src/cli.ts(50%). Focus on option-parsing and error-path branches.4. Add tests for the storage-propagation helpers (
createStoragePropagationEvidence,observeStorageMount,assertPrivateStorageMount) and forresolveRunSandboxBackend/validateRunSandboxBackend, added in the last 7 days.Low
5. Improve
src/bounded-execution/finite-disclosure.ts(11.42% branch),src/bounded-execution/finite-schema.ts(56.88% branch), andsrc/microvm/network-reservation.ts(54.86% branch).Generated by test-coverage-reporter workflow. Trigger:
scheduleAll reactions